URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: twogirlscleaning.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2020-10-21 14:07:11 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)
A record(s) observed :2

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-07-23 10:18:27 199.59.243.228Not listedAS16509 AMAZON-02- USno
2020-10-21 14:07:17 172.104.22.215172-104-22-215.ip.linodeusercontent.comNot listedAS63949 AKAMAI-LINODE-AP- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-10-26 23:29:03http://twogirlscleaning.com/wp-content/6uLgyTvC...Offlinedoc emotet ext epoch2 heodo ext Cryptolaemus1
2020-10-21 14:07:17http://twogirlscleaning.com/openbayl/KaI/Offlineemotet ext epoch1 exe heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-10-27 01:08:46c8b394c2d8b83573eba859ba30101e535e3795cc846b6f21a09c3653cae36981docHeodo
2020-10-27 00:52:39f5831fd5a2bd8c3eaf0bbd799764d684f1c3a2528d5583013b438e6f2b4f4843docHeodo
2020-10-27 00:44:200779c9b1561c39e278910257e807a233b3545da40dd442a26906c0ffa6e199fbdocHeodo
2020-10-27 00:22:19277c9a5a3210a4fa589ee6ad368ca72eb54f66de900e476082a8167f6b3ba55bdocHeodo
2020-10-27 00:09:58d3cf19d985ba239666e0baf1a161de4dfc1f49327d23ec569370538e782ceebbdocHeodo
2020-10-26 23:39:23ac739c4d98aa46329d4ebe114bad66247375ddaf8d148446712f2a2b8006f300docHeodo
2020-10-26 23:29:0395915a361b85e01938f5a7747c45514c7d919a5af28980e1bb258303c6e7a167docHeodo
2020-10-21 20:46:020677cb5a6f56a82009384138f05171135158d441b07b10009cd50621dc397a61exe Heodo
2020-10-21 20:17:10f7db9c0acbe793fb730673528dd60cf01e528cc599cfcc2ba129eb0e40e08933exe Heodo
2020-10-21 19:51:09b868fa34852d29b43ed665a936c2f9e4cac7de5720edd34f0485e4c4d21136aeexe Heodo
2020-10-21 19:29:28d7a51b820e8ec38d04ca5f99f536086e330d566d3e84bbf4ee346b604dedadbdexe Heodo
2020-10-21 18:35:117c52c5c304efff6ff5a079334682d2483a634acb9ca75799643edfe67231886bexe Heodo
2020-10-21 17:51:56814c913c2259c6aa282851bad4c3ef23e01d95f8fbb1cbd41e0816e9e7e0d22eexe Heodo
2020-10-21 17:27:1400843ed494e8148a67ec8ac97f2d98144b701a025156719afbca32ce1c394d55exe Heodo
2020-10-21 14:29:083762394e5ffefc1d408b6dec7a46accde3f5b2f8d15bd62873f9b5fd03757035exe Heodo
2020-10-21 14:07:178108561c5abc24af14a93288422d36acbd9cfd30c8cf063bc8ab522147b045f0exe Heodo